Follow Blog via Email

Enter your email address to follow this blog and receive notifications of new posts by email.

Sites I like

Enabling root SSH login on an ESX host

The oldies are the best ones – I always forget this when I get stumped by weird vRanger/vReplicator issues- from VMware.com:

Details

This article provides steps to use SSH to login to an ESX host as the root user.

Solution

Since ESX 3.0, for increased security, SSH is disabled by default for the root account on an ESX host. That is, the actual sshd service does not allow root logins. Non-root users are able to login with SSH. This is another layer of protection in addition to the host firewall.

Note: Each SSH connection to an ESX host uses additional Service Console resources. Use caution when using scripts or third party software that create multiple SSH sessions to the ESX Service Console. Excessive use of SSH on an ESX machine may cause the service console to exhibit symptoms of memory exhaustion.

To enable root login for SSH and SCP clients:

If you have physical access to the ESX host, login to the console of your ESX host as the root user. If you can only connect to the ESX host over the network, connect using an SSH client (such as PuTTY) and log in as a user other than root.

To create a user in ESX host for using a SSH client:

Log in to the vSphere Client as a root user.

Click Users & Groups.

Right-click on a blank area and click Add.

Enter a username and password. Confirm your password.

Note: Starting in ESX 4.0, the password needs to be at least 8 characters in length.

Select Grant shell access to this user and click OK.

After you are logged in SSH session, switch to the root user with the command:

su –

Note: If you do not have any other users on the ESX host, you can create a new user by connecting directly to the ESX host with VMware Infrastructure (VI) or vSphere Client. Go to the Users &Groups tab, right-click on the Users list and select Add to open the Add New User dialog. Ensure that the Grant shell access to this useroption is selected. These options are only available when connecting to the ESX host directly. They are not available if connecting to vCenter Server.

Edit the configuration file for SSH with the command:

nano /etc/ssh/sshd_config

Find the line that starts with PermitRootLogin and change the no to yes. You can find this line about 2 pages down from the top. Save the file by first pressing Ctrl-O and then Enter. Exit with Ctrl-X.